Operations
Day-two BRIDGE: the dashboard, the CLI, the API, and the service manager.
Dashboard tour
The embedded operations dashboard is a dark, Cloudflare-inspired ops console served
by the daemon itself: no separate process. By default it listens on
http://127.0.0.1:9090 (loopback only). Its views:
| View | What it shows |
|---|---|
| Overview | Fleet at a glance: node count, leader, routes, and current handoff tier. |
| Nodes | Every known member with its lifecycle state (Alive / Suspected / Dead / Recovered), endpoint, and priority. |
| Mesh | The WireGuard overlay: mesh IPs, links, and connectivity between nodes. |
| Routes | Static and Docker-discovered routes, their upstreams, and consistent-hash targets. |
| Events | Real-time event feed streamed over WebSocket: elections, handoffs, membership changes, failovers. |
| Config | The running configuration as loaded by the daemon. |
CLI reference
The bridge CLI talks to the running daemon over its Unix socket
(/tmp/bridge.sock, see [ipc]).
| Command | Description |
|---|---|
bridge status | Daemon and fleet summary: uptime, role (leader/follower), membership counts. |
bridge routes | List all routes, static and discovered. |
bridge add-route | Add a route to the running daemon. |
bridge remove-route | Remove a route from the running daemon. |
bridge cluster | Show cluster membership and each node's lifecycle state. |
bridge inspect <domain> | Inspect the route and upstream resolution for a hostname. |
bridge replicas | Show failover-duplication replicas and their placement. |
bridge ping | Check that the daemon answers over the IPC socket. |
Health endpoint
GET /health on the dashboard listener reports daemon health, suitable
for load-balancer or monitoring checks:
curl -fsS http://127.0.0.1:9090/health
JSON API
The dashboard listener also serves a JSON API under /api/v1, plus a
WebSocket stream for real-time events:
| Endpoint | Description |
|---|---|
GET /api/v1/status | Daemon and fleet status. |
GET /api/v1/nodes | Cluster members and lifecycle states. |
GET /api/v1/routes | Configured and discovered routes. |
GET /api/v1/mesh | WireGuard mesh topology. |
GET /api/v1/events | Recent events. |
GET /api/v1/handoff | Current handoff tier and state. |
GET /api/v1/config | Running configuration. |
WS /api/v1/stream | Real-time event stream (the same feed the dashboard renders). |
systemd management
The installer registers bridge.service:
systemctl status bridge # service state
systemctl restart bridge # pick up a config change
journalctl -u bridge -f # follow daemon logs
The unit runs the daemon as the unprivileged bridge user with
CAP_NET_BIND_SERVICE and CAP_NET_ADMIN: enough to bind
ports 80/443 and configure WireGuard without full root.
Graceful shutdown
On stop or restart, the daemon's shutdown coordinator drains subsystems in order (ingress first, background workers last) and persists state to disk. A restarted node resumes from the last known fleet state instead of rejoining cold.
Upgrading
Re-run the installer. It downloads and verifies the new release, replaces the binary,
and restarts the service. Your existing /etc/bridge/bridge.toml is never
overwritten. Pin a specific version when you want a controlled rollout:
curl -fsSL https://bridgemesh.space/install.sh | sh
# or pin a version:
curl -fsSL https://bridgemesh.space/install.sh | BRIDGE_VERSION=v1.2.3 sh
Upgrade followers first and the leader last: the fleet re-elects a follower as leader, hands off the ingress, and the old leader rejoins after its upgrade.